Repository navigation
Conversation
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
📒 Files selected for processing (10)
Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 8 remain after this review. WalkthroughThe resolver distinguishes dynamic imports from other ESM resolution, passes import-kind labels to ChangesResolver plugin flow
Suggested reviewers: Priority: ⬇️ Low Merge Risk: ⚪ Minimal · up to The identified concerns do not block merging. The callback kind is documented, and a panic cannot leave a running process with the reported stale resolver state. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to Registered plugins can redirect more package imports, while builtin, nested-resolution, and custom-search-path safeguards remain. No introduced security flaw was established. Dynamic-import classification still depends on a timing assumption that could not be fully verified. Retained concerns Security review detailsSecurity Blast Radius
Trust Boundaries and Controls
Resilience and Maintainability Implications
🚥 Pre-merge checks | ✅ 4✅ Passed checks (4 passed)
Comment |
Carry caller intent across the Rust/C++ plugin boundary and consume the synchronous dynamic-import marker before callbacks can reenter resolution. Retain static, require, require.resolve and runtime resolver distinctions. Use oven-sh#44593's bare-alias guards adapted from @robobun's oven-sh#40398. Preserve original assertions and add static-import and nested-resolution coverage.
d08c5c0 to
0b6811f
Compare
|
Reworked kind propagation at #44473's single runtime resolve. The dynamic-import marker is consumed before plugin reentry; static and nested resolution retain their own kind. Bare aliases use #44593/#40398's guarded dispatch. On macOS arm64 against 9bd19c9, the original plugin file had 95 pass / 1 fail; the refreshed file has 97 pass / 0 fail, including added static/nested coverage. Query resolution passes 15 tests; P2 review is clean. |
What does this PR do?
Exposes runtime onResolve import kinds through #44473's resolve-once loader. Dynamic imports pass their kind into the first resolver dispatch; that marker is consumed before calling plugins, so nested resolutions and static imports keep their own kinds. The Rust/C++ boundary reports dynamic-import, require-call, require-resolve, or import-statement as appropriate.
Bare-alias admission uses the same guarded dispatch as #44593, adapted from @robobun's #40398. Builtins, nested bare imports and custom search paths retain their existing exclusions. No PluginRunner or second loader resolve is restored.
How did you verify your code works?
Built on macOS arm64 against main 9bd19c9. The full plugin file passes 97 tests, retaining the original kind assertions and adding static-import/nested-resolution coverage. The query-string resolution file passes 15 tests. Independent review through P2 is clean. No new cross-platform or ASAN qualification is claimed.